PQC Archives - Intelligence Community News https://intelligencecommunitynews.com/tag/pqc/ Breaking news about the market for products, systems and services for the U.S. intelligence community Mon, 18 May 2026 12:53:32 +0000 en-US hourly 1 https://wordpress.org/?v=7.0 https://intelligencecommunitynews.com/wp-content/uploads/2018/10/cropped-ICN-square-logo-400-32x32.jpg PQC Archives - Intelligence Community News https://intelligencecommunitynews.com/tag/pqc/ 32 32 59882712 Transitioning to Post-Quantum Cryptography: What Federal Agencies Must Do Now https://intelligencecommunitynews.com/ic-insiders-44593-2/?utm_source=rss&utm_medium=rss&utm_campaign=ic-insiders-44593-2 Mon, 18 May 2026 12:53:32 +0000 https://intelligencecommunitynews.com/?p=44593 From IC Insider Thales Trusted Cyber Technologies By Gina Scinta, Deputy CTO, Thales Trusted Cyber Technologies Has your agency begun...

The post Transitioning to Post-Quantum Cryptography: What Federal Agencies Must Do Now appeared first on Intelligence Community News.

]]>
From IC Insider Thales Trusted Cyber Technologies

By Gina Scinta, Deputy CTO, Thales Trusted Cyber Technologies

Has your agency begun its strategy for transitioning to post-quantum cryptography (PQC)? If you’re not fairly far along now, you’re actually a bit behind. New guidance from the administration this past March, along with a memo from the Department of War last year, is ramping up the urgency. In fact, some of the stalwart cryptographic solutions used in the federal sector will be given the axe in the next five years.

Fortunately, there are some simple steps you can follow to start gearing up for your PQC transition. We’ll address those steps in a moment, but let’s first understand the context of this increasingly pressing need for dealing with security in a post quantum world.

Cyber Strategy and the Push for Infrastructure Security

March 2026 saw the release of this administration’s Cyber Strategy for America. The strategy organizes priorities around six “pillars of action,” each of which has direct implications for both federal contractors and agency cybersecurity teams. Two of those pillars are particularly relevant to this discussion: securing critical infrastructure and modernizing and securing federal government networks.

The modernization pillar in particular calls for accelerating the adoption of cybersecurity best practices, PQC, zero-trust architecture, and the transition to the cloud. This is part of the administration’s desire to have decisions made and implemented at the agency level more quickly.

PQC is becoming essential in securing federal networks. And, the Cyber Strategy comes as the Department of War has announced prioritization of solutions using NIST- approved, CNSA 2.0-listed PQC algorithms in lieu of previously-accepted quantum resistant solutions that make use of symmetric key management protocols. The Department will cease to test, pilot, use, or procure commercial solutions using these symmetric key technologies for quantum resistance. So, for agencies and contractors still relying on any of those solutions, the clock is running.

Why the urgency? Experts project the first cryptographically relevant quantum computers could emerge as early as the next decade.

Protecting systems from the quantum computing threat can’t wait until 2030. Harvest now, decrypt later schemes involve collecting data encrypted with classical algorithms today and decrypting it once a sufficiently powerful quantum computer exists. Intelligence, personnel records, and operational communications being transmitted right now are being targeted with this in mind. This is not a future problem.

Meanwhile, past cryptographic migrations across federal landscape have taken over a decade. From a purely historical perspective, things are already behind schedule.

On top of all this guidance, it’s important to remember that NIST released its first finalized PQC standards in August 2024, and is now in the process of deprecating specific cryptographic primitive algorithms and schemes on a set schedule. Agencies that have not migrated before those cutoff dates will be running deprecated cryptography in critical systems.

A Migration Memo to the Department of War

Back in November 2025, the Department of War released a memo titled, “Preparing for Migration to Post Quantum Cryptography.” The memo was directed to senior Pentagon leadership, combat commands and field activity directors, and laid the groundwork for migrating to PQC. (This guideline memo builds on the Quantum Computing Cybersecurity Preparedness Act of 2022, which requires agencies develop a PQC transition timeline based on their assessment of how they use potentially vulnerable cryptography.)

“Advancements of Quantum Information Science (QIS) and cryptanalytically relevant quantum computers requires expedited migration to quantum-resistant cryptography to safeguard the Department’s information systems, communications, and personnel,” the November 2025 memo reads.

It goes on to say, “The migration to post quantum cryptography (PQC) must not only be planned and executed with deliberate urgency to maintain warfighter lethality and information dominance in the DoW global ecosystem, but also strategically coordinated…To achieve this level of coordination, we must identify PQC migration points of contact for information sharing and create processes for streamlining intake and prioritization of PQC solutions to support certification activities and timelines.”

The Department’s memo stresses that agencies must receive cryptographic intake and deployment approval before testing, evaluating, piloting, investing in, using, or deploying any quantum-resistant or quantum-resilient technologies. It also bans outright a set of technologies for use in providing confidentiality, authenticity, or integrity on DoD networks:

  • Quantum Key Distribution (QKD)
  • Solutions combining QKD with other cryptographic keys
  • Quantum communications or networking
  • Non-local quantum randomness generation
  • Non-FIPS random number generation

 

Providing quantum resistance in solutions using cryptographic pre-shared keys (PSK) not provisioned through NSA Key Management Infrastructure for Type 1 devices will be sundowned on December 31, 2030. Symmetric Key Establishment, Agreement, and Distribution Protocols will be eliminated a year later, on December 31, 2031.

For future solutions, underlying technology must include crypto agility.

Crypto Agility: The Requirement Behind the Requirement

As organizations prepare for the post‑quantum era, crypto agility becomes essential—enabling systems to adopt PQC algorithms rapidly, minimize operational disruption, and remain resilient as cryptographic standards evolve. Many long‑established cryptographic programs have already internalized these principles, giving them the architectural headroom to absorb PQC’s larger key sizes and increased computational demands with minimal friction. NIST’s Cybersecurity White Paper CSWP 39 reinforces this need by detailing the tradeoffs, operational challenges, and interoperability considerations inherent in achieving true cryptographic agility.

For agencies, the actionable takeaway is clear: every modernization or procurement decision should explicitly require demonstrable crypto‑agility, ensuring that systems acquired today can adapt to tomorrow’s PQC mandates instead of becoming tomorrow’s technical debt. This shifts crypto agility from an abstract aspiration to a concrete acquisition criterion that safeguards mission longevity.

As organizations transition into the post‑quantum era, crypto agility becomes essential—enabling systems to rapidly adopt PQC algorithms, minimize operational disruption, and stay resilient against evolving cryptographic threats.

Seven Steps to a PQC Transition Strategy

So what are the steps agencies must take in developing their PQC transition strategy? There are seven:

  • Awareness
  • Inventory technology/prioritize systems
  • Automate crypto discovery
  • Automate inventory
  • Set up a PQC test environment
  • Practice crypto agility
  • Apply quantum key generation and implement quantum-resistant algorithms

 

Let’s take a quick look at each step.

Awareness. Your transition strategy is a top-down initiative. Leadership must be fully aware of the challenge: not only the risks, but the specific actions required to meet them. The harvest now, decrypt later threat means that PQC migration isn’t a future budget line, it’s an active operational risk.

Inventory cryptographic technologies and prioritize high-risk systems. The Office of the National Cyber Director (ONCD) provided specific instructions to federal agencies on inventorying their cryptographic systems. ONCD directed agencies to submit prioritized cryptographic inventories by May 2023. For many, unfortunately, that was a paper exercise. A manual process is less precise than one using available electronic tools, and your cryptographic footprint has grown since that submission.

Automate crypto discovery. Crypto inventory is not a one-time task. Organizations continuously create new cryptographic instances across their environments. Automated discovery is the only practical way to maintain an accurate picture. You cannot migrate what you have not mapped.

Automate discovery and inventory. Multiple vendors offer automated cryptographic discovery tools. Assess what is available and match tools to your environment. Automated tooling surfaces cryptographic dependencies that manual processes miss entirely.

Set up a PQC test environment. Now that the NIST standards are finalized, it is time to upgrade your environment for testing. As previously noted, PQC algorithms generate larger keys, and the performance impact of those larger keys could affect your systems in ways you had not anticipated. Test before you deploy at scale.

Practice crypto agility. Supporting both classical and PQC algorithms simultaneously is what makes an organization crypto agile. Devices and platforms being procured today must be capable of this. If they are not, you have to begin modernizing those systems now.

Apply quantum key generation and implement quantum-resistant algorithms. The foundation of encryption is the quality of the cryptographic keys. Organizations should leverage a quantum random number generator (QRNG) to produce high-quality entropy as the basis for all keys and cryptographic operations. Encryption solutions must use the standardized NIST PQC algorithms, or be crypto-agile with a clear and near-term upgrade path to them.

The administration’s Cyber Strategy, the Department of War phase-out deadlines, and the NIST deprecation schedule all point in the same direction: Cryptographically dangerous quantum computers are coming, and the threat is real.

Agencies should plan their transition strategies now work. Automate your crypto discovery, stand up a PQC test environment, require crypto agility in new procurements, and prioritize migration on your highest-risk systems first.

Industry has been working on this for years. Agencies need to close the gap.

About Thales TCT

Thales Trusted Cyber Technologies, a business area of Thales Defense & Security, Inc., protects the most vital data from the core to the cloud to the field. We serve as a trusted, U.S. based source for cyber security solutions for the U.S. Federal Government. Our solutions enable agencies to deploy a holistic data protection ecosystem where data and cryptographic keys are secured and managed, and access and distribution are controlled.

For more information, visit www.thalestct.com

About IC Insiders

IC Insiders is a special sponsored feature that provides deep-dive analysis, interviews with IC leaders, perspective from industry experts, and more. Learn how your company can become an IC Insider.

The post Transitioning to Post-Quantum Cryptography: What Federal Agencies Must Do Now appeared first on Intelligence Community News.

]]>
44593
Leidos joins NIST PQC consortium https://intelligencecommunitynews.com/leidos-joins-pqc-nist-consortium/?utm_source=rss&utm_medium=rss&utm_campaign=leidos-joins-pqc-nist-consortium Wed, 04 Mar 2026 13:17:17 +0000 https://intelligencecommunitynews.com/?p=43987 On March 2, Leidos announced its inclusion in NIST’s Post-Quantum Cryptography Consortium. NIST’s Post-Quantum Cryptography Consortium is a groundbreaking initiative...

The post Leidos joins NIST PQC consortium appeared first on Intelligence Community News.

]]>
On March 2, Leidos announced its inclusion in NIST’s Post-Quantum Cryptography Consortium.

NIST’s Post-Quantum Cryptography Consortium is a groundbreaking initiative to simplify cryptographic discovery, ease migration complexity, and promote system interoperability post-migration. This achievement positions Leidos as a leader in the race to secure the future, underscoring commitment to driving innovation, shaping policy, and delivering scalable, secure solutions for federal missions and critical infrastructure, according to the company.

Quantum computing promises to unlock new possibilities in science, technology, and industry — but it also threatens to disrupt the very foundations of classical cryptography. Traditional encryption methods, which protect sensitive data and secure communications, could be rendered ineffective by the immense computational power of quantum computers.  Recognizing this urgent challenge, NIST established the Post-Quantum Cryptography Consortium to ease the transition to their post-quantum cryptographic standards. This initiative is critical essential to strengthening the resilience of mission-critical systems and protect national security in the quantum era.

As a member of the consortium, Leidos will play a pivotal role in advancing research and shaping policy for the migration to post-quantum cryptography. The company’s deep expertise in cybersecurity, mission-critical systems, and cryptographic modernization uniquely positions us to contribute to this vital effort, Leidos said.

Source: Leidos

Stay in the know with breaking news from across the IC and IC contracting landscape by becoming a paid subscriber to IC News. Your support makes our work possible.

The post Leidos joins NIST PQC consortium appeared first on Intelligence Community News.

]]>
43987
ISARA and Carahsoft partner https://intelligencecommunitynews.com/isara-and-carahsoft-partner/?utm_source=rss&utm_medium=rss&utm_campaign=isara-and-carahsoft-partner Tue, 27 Jan 2026 14:41:53 +0000 https://intelligencecommunitynews.com/?p=43695 On January 22, ISARA Corporation and Carahsoft Technology Corp. announced a partnership. Under the agreement, Carahsoft will serve as ISARA’s public sector...

The post ISARA and Carahsoft partner appeared first on Intelligence Community News.

]]>
On January 22, ISARA Corporation and Carahsoft Technology Corp. announced a partnership. Under the agreement, Carahsoft will serve as ISARA’s public sector distributor, making the company’s quantum readiness solutions available to the public sector through Carahsoft’s reseller partners and NASA Solutions for Enterprise-Wide Procurement (SEWP) V, Information Technology Enterprise Solutions – Software 2 (ITES-SW2), The Interlocal Purchasing System (TIPS), National Association of State Procurement Officials (NASPO) ValuePoint, OMNIA Partners, E&I Cooperative Services Contract and The Quilt contracts.

Together, the companies will help federal agencies accelerate quantum-safe cryptography readiness by implementing autonomous cryptographic posture management with Post-Quantum Cryptography (PQC) implementations to prepare for the post-quantum era.

“As the Department of War’s (DoW) recent memorandum makes clear, the migration to post quantum cryptography is an urgent national security priority that begins with comprehensive cryptographic discovery and inventory, aligned with OMB Memorandum 23-02 and CNSS Policy 15,” said Jim Sortino, CRO of ISARA. “As the quantum computing security threat becomes more imminent, enterprises and agencies are moving from reactive defense to proactive resiliency in order to comply with U.S. cryptographic modernization mandates.”

ISARA, in partnership with Carahsoft, will enable DoW components and U.S. federal agencies to quickly gain visibility into their cryptography so they can move with confidence toward quantum resistant solutions, crypto agility and architectural validation.

The partnership aligns with the government’s growing emphasis on quantum readiness and supports efforts to enhance ZTA plans by safeguarding national digital infrastructure and mission-critical systems from emerging threats. It combines ISARA’s expertise in cryptographic risk management and quantum-safe enablement with Carahsoft’ expertise in cybersecurity, large-scale technology transformation and Federal mission operations.

Through ISARA’s partnership with Carahsoft, federal agencies will gain access to a full suite of quantum readiness services, including cryptographic inventory, assessments, prioritization through cryptographic posture management, roadmap development, quantum-safe operational technology (OT) enablement, PQC implementations and crypto-agility solutions, the companies said.

“Together with ISARA and our network of reseller partners, we can help our federal clients proactively defend against future-state risks while modernizing their cybersecurity infrastructure in alignment with evolving federal mandates,” said Brian O’Donnell, vice president of cybersecurity solutions at Carahsoft. “We’re providing a practical, phased approach to quantum readiness, one that helps agencies manage cryptographic risk today and strengthen their security for tomorrow.”

Source: Carahsoft

Start 2026 ahead of the competition with a paid subscription to IC News. You’ll get full access to our searchable archive of 15,000+ articles, plus new articles each weekday.

The post ISARA and Carahsoft partner appeared first on Intelligence Community News.

]]>
43695
Inside the Mission – Automating Cryptographic Discovery and Risk for the Quantum Era https://intelligencecommunitynews.com/ic-insiders-inside-the-mission-automating-cryptographic-discovery-and-risk-for-the-quantum-era/?utm_source=rss&utm_medium=rss&utm_campaign=ic-insiders-inside-the-mission-automating-cryptographic-discovery-and-risk-for-the-quantum-era Wed, 10 Dec 2025 13:01:13 +0000 https://intelligencecommunitynews.com/?p=43372 From IC Insider Tychon Manual Cryptography Inventory: A Hidden Operational Burden Across the Intelligence Community (IC), cybersecurity teams have faced...

The post Inside the Mission – Automating Cryptographic Discovery and Risk for the Quantum Era appeared first on Intelligence Community News.

]]>
From IC Insider Tychon

Manual Cryptography Inventory: A Hidden Operational Burden

Across the Intelligence Community (IC), cybersecurity teams have faced an unexpected challenge: finding and cataloging every instance of encryption in use. Whether it’s a TLS certificate, a VPN configuration, or an embedded algorithm in a mission system, each represents a potential vulnerability in a quantum future.

Most agencies today rely on spreadsheets, manual scripts, and ad hoc tools to attempt discovery, an approach that consumes thousands of analyst hours, delays compliance with OMB M-23-02 and NSM-10, and leaves decision-makers blind to emerging risks.

The problem isn’t effort. It’s visibility.

The Need for Continuous, Automated Discovery

Every encryption key, certificate, and cipher suite deployed across an enterprise is a potential weak point once quantum computers arrive. Agencies need more than one-time inventories; they need continuous visibility and risk scoring.

Automation is the only viable path forward. Without it, cryptographic inventories grow stale within weeks, and remediation plans are based on outdated assumptions.

Tychon Quantum Readiness delivers exactly that. Continuous, automated cryptography discovery, inventory, and risk assessment that’s built for scale and designed for the complexity of IC networks.

Engineered for Mission Simplicity

Unlike legacy cryptography management tools that require heavy infrastructure, agents, or separate consoles, Tychon deploys as a stateless binary. It runs with no persistent services or external dependencies, and it integrates directly with existing endpoint and systems management tools including BigFix, Intune, SCCM, and Ansible.

This design makes Tychon ideal for secure and air-gapped environments:

  • No new agents or network appliances required
  • No proprietary dashboards to train on
  • Deployment measured in hours, not months
  • Zero operational friction across classified and unclassified domains
  • No additional servers, databases, or external calls
  • Extensive reporting options to include CBOM, CSV, JSON and more

A SIEM-First Design for Real-Time Insight

Tychon’s architecture reflects a SIEM-first philosophy that is designed to feed cryptographic visibility directly into mission systems that already exist.

It integrates natively with BigFix, Elasticsearch, Splunk, Axonius, and Armis, streaming continuous diagnostics and cryptography risk telemetry into the same dashboards security teams already use.

Pre-built dashboards instantly surface:

  • Protocols and ciphers in use
  • Certificates nearing expiration or using deprecated algorithms
  • Key lengths and curve types
  • Cryptographic libraries and binaries detected in applications

 

No retraining. No console switching. No data silos.

From Static Spreadsheets to Continuous Compliance

Federal policy has accelerated the demand for live cryptographic visibility. Under OMB M-23-02, agencies must not only complete a one-time cryptography inventory but also report ongoing progress and risk posture.

Tychon automates this requirement, generating NIST-aligned reports and dashboards for OMB, NSM-10, and CISA CDM compliance frameworks.

By automating data collection, normalization, and scoring, Tychon reduces cryptographic inventory costs by up to 90 percent, eliminating more than 1,200 staff hours per reporting cycle.

Risk Scoring that Speaks the Language of Mission Owners

Not all cryptography carries equal risk. Tychon’s integrated scoring engine quantifies exposure based on algorithm age and strength, key length, implementation type, system criticality, and quantum vulnerability.

This NIST-aligned scoring model helps agency leaders to mission program managers prioritize mitigation efforts and budget allocations.

It also supports hardware readiness analysis by identifying systems unable to support PQC algorithms. This is a crucial insight for hardware budget lifecycle and modernization planning.

Security Without Trade-Offs

Security and simplicity rarely coexist, but Tychon achieves both. The self-contained binary includes all required libraries internally, eliminating dependency risks. It’s easy to hash, verify, and attest for supply-chain integrity.

Data never leaves the customer’s environment. Role-based access, audit logging, and FIPS-validated components ensure that the system meets the security bar expected by DoW, IC, and FCEB environments.

Proven at Mission Scale

Tychon’s technology is battle-tested at scale. The same engine that underpins Tychon Quantum Readiness has been operational across the U.S. Army’s global enterprise, more than 800,000 endpoints, for over eight years.

In classified and disconnected environments, Tychon continues to deliver real-time cryptographic telemetry with unmatched performance and reliability.

For the IC, this means confidence that the same solution proven in the world’s largest defense networks can extend securely into sensitive mission systems.

Why It Matters to the Intelligence Community

Quantum readiness is not a compliance checkbox, it is an operational continuity issue. Encryption is the foundation of every IC mission: protecting data at rest, authenticating users, securing communications, and maintaining trust in classified networks.

Losing confidence in that foundation could have cascading effects on national security operations.

By automating the discovery and management of cryptography, Tychon helps IC organizations transition from fragmented, manual visibility to continuous, data-driven assurance.

A New Seamless Path to PQC Readiness for BigFix Customers

BigFix customers now have the option to activate Tychon’s Quantum Readiness capabilities as a native BigFix offering, eliminating the need for additional tools or integrations. This direct integration allows agencies to perform automated cryptographic discovery and risk assessment using the same BigFix workflows they already trust for endpoint management. By leveraging BigFix’s deployment scale, agencies gain immediate visibility into quantum-vulnerable algorithms, certificates, and keys across every managed system. This new offering, known as BigFix Quantum Risk Analyzer, dramatically accelerates compliance efforts and enables a seamless path to PQC transition planning. This combined new solution will be generally available to BigFix customers for trial or purchase in January 2026.

The Future: Continuous Cryptography Intelligence

The next era of cybersecurity will not simply monitor threats, it will monitor the integrity of cryptography itself. With Tychon, agencies stream cryptographic telemetry into their preferred SIEM, business intelligence, and big data platforms for continuous diagnostics and mitigation, aligning perfectly with Zero Trust and PQC transition initiatives.

Request a live demonstration to see Tychon Quantum Readiness in action. Automate your cryptography visibility within hours, not months. Contact info@tychon.io or visit tychon.io.

About Tychon

TYCHON is a NIST NCCoE consortium collaborator and proven cybersecurity innovator delivering automated cryptography discovery and quantum-readiness solutions across U.S. Federal, DoW, and commercial enterprises. Tychon provides instant cryptographic visibility, risk assessment, and compliance reporting for the post-quantum era.

Sponsored content provided by Tychon LLC, a NIST NCCoE consortium collaborator for PQC.

About IC Insiders

IC Insiders is a special sponsored feature that provides deep-dive analysis, interviews with IC leaders, perspective from industry experts, and more. Learn how your company can become an IC Insider.

The post Inside the Mission – Automating Cryptographic Discovery and Risk for the Quantum Era appeared first on Intelligence Community News.

]]>
43372
Patero and Carahsoft partner https://intelligencecommunitynews.com/patero-and-carahsoft-partner/?utm_source=rss&utm_medium=rss&utm_campaign=patero-and-carahsoft-partner Tue, 09 Dec 2025 02:09:24 +0000 https://intelligencecommunitynews.com/?p=43355 On December 8, Carahsoft Technology Corp. and Patero Inc., a pioneer in cryptographic inventory and post-quantum encryption, announced a partnership to...

The post Patero and Carahsoft partner appeared first on Intelligence Community News.

]]>
On December 8, Carahsoft Technology Corp. and Patero Inc., a pioneer in cryptographic inventory and post-quantum encryption, announced a partnership to distribute Patero’s cryptography discovery, inventory, quantum risk assessment, and compliance reporting solution, PanoQoR, to the public sector. Under the agreement, Carahsoft will serve as Patero’s Master Government Aggregator, making the company’s quantum computing solutions available to the public sector through Carahsoft’s reseller partners and NASA Solutions for Enterprise-Wide Procurement (SEWP) V, Information Technology Enterprise Solutions – Software 2 (ITES-SW2), National Association of State Procurement Officials (NASPO) ValuePoint and OMNIA Partners contracts.

“The shift to post-quantum cryptography is not theoretical, it’s operational,” said Peter Bentley, chief operating officer at Patero. “Agencies must know what encryption they have today before they can protect what matters tomorrow. Carahsoft’s unmatched public sector network makes them the ideal partner to scale this capability in the U.S. and Canada.”

Sufficiently powerful quantum computers could crack the asymmetric encryption currently used by governments and civilian organizations worldwide. In May 2022, the White House issued National Security Memorandum 10 to address the risk posed by quantum computing to encrypted data and information systems. Subsequently, OMB issued Memorandum M-23-02, which requires agencies to submit an annual prioritized inventory of information systems and assets that contain cryptographic systems vulnerable to quantum attacks.

Carahsoft’s Quantum Solutions Team now distributes Patero’s PanoQoR cryptography inventory solution to help meet this mandatory inventory requirement for its Federal, defense, and critical infrastructure customer base. Establishing a cryptography inventory, quantum risk assessment, and compliance reporting solution not only meets Federal and civilian regulatory requirements but also represents the first step toward migrating from legacy encryption methods to post-quantum cryptography (PQC) for protecting sensitive data and systems.

“Quantum computing will redefine cybersecurity,” said Troy Meraw, quantum solutions program manager at Carahsoft. “By bringing Patero’s cryptographic inventory and PQC remediation tools to our government and enterprise customers, Carahsoft and our reseller partners are enabling security leaders to take proactive steps now to meet mandates.”

Source: Carahsoft

Don’t miss out — become a paid subscriber to IC News, and lock in subscription rates at 2025 prices. You’ll get full access to breaking news from across the IC contracting space, with new articles each weekday.

The post Patero and Carahsoft partner appeared first on Intelligence Community News.

]]>
43355
The Urgency of Quantum Readiness – What the Intelligence Community Needs to Know Now https://intelligencecommunitynews.com/ic-insiders-the-urgency-of-quantum-readiness-what-the-intelligence-community-needs-to-know-now/?utm_source=rss&utm_medium=rss&utm_campaign=ic-insiders-the-urgency-of-quantum-readiness-what-the-intelligence-community-needs-to-know-now Thu, 20 Nov 2025 02:52:13 +0000 https://intelligencecommunitynews.com/?p=43223 From IC Insider Tychon The Quantum Countdown Quantum computing has moved from theoretical curiosity to technological inevitability and with it...

The post The Urgency of Quantum Readiness – What the Intelligence Community Needs to Know Now appeared first on Intelligence Community News.

]]>
From IC Insider Tychon

The Quantum Countdown

Quantum computing has moved from theoretical curiosity to technological inevitability and with it comes one of the largest security transitions in modern history. When Dr. Peter Shor unveiled his algorithm in 1994, the world learned that quantum computers could one day break the public-key encryption that protects everything from battlefield communications to classified research and national intelligence data.

That day, commonly known as “Q-Day,” may be closer than many think. Dr. Michele Mosca, one of the world’s foremost experts in quantum computing timelines, gives Q-Day a 1-in-7 chance by 2026 and a 50 percent chance by 2031. For the Intelligence Community (IC), where adversaries continuously collect encrypted traffic to decrypt later (“Harvest Now, Decrypt Later”), this risk is immediate.

There will be an immediate impact if large scale quantum computers emerge

  • Breaking RSA, Diffie–Hellman, and ECC – the algorithms that protect most classified and unclassified government communications.
  • Compromising diplomatic, military, and IC networks that still rely on classical public-key cryptography.
  • Identity theft of government credentials, including digital signatures.

Harvest Now, Decrypt Later Is Already Here

Adversaries do not need to wait for Q-Day. Many already intercept and store encrypted communications today with the expectation that they can decrypt them once quantum computing power matures. Data collected now such as diplomatic cables, SIGINT and HUMINT communications, Intelligence sharing arrangements or even sensitive personnel records may be exposed years later. What is at risk, historical operational TTPs, sources, networks, covert methods, OPSEC, and more to provide our adversaries with a greater understanding of U.S. Intelligence.

The only defense is proactive migration to quantum-safe algorithms, known collectively as Post-Quantum Cryptography (PQC).

PQC Mandates Are in Motion

Federal and IC organizations are not starting from scratch. A series of policies and directives are already shaping the national PQC roadmap:

  • OMB M-23-02 – Requires agencies to inventory and assess cryptography, report on quantum-susceptible algorithms, and establish PQC transition plans.
  • NSM-10 – Directs agencies to protect National Security Systems (NSS) from quantum threats.
  • NIST PQC Standards – Algorithms like CRYSTALS-Kyber and CRYSTALS-Dilithium are being standardized into Federal Information Processing Standards (FIPS) for broad adoption.

 

Together, these mandates demand one critical capability: knowing what cryptography you have, where it resides, and whether it’s quantum-vulnerable.

The Four Phases of Quantum Readiness

Every organization, from mission system owners to intelligence analysts, will need to navigate four core phases of quantum readiness:

  1. Information Discovery: Identify systems, data flows, and communication channels using encryption.
  2. Cryptography Inventory: Locate every algorithm, key, and certificate in use.
  3. Risk Assessment & Analysis: Determine which assets are quantum-susceptible and prioritize remediation.
  4. Remediation & Migration: Replace vulnerable cryptography and modernize systems for PQC.

 

Manually completing these steps across hundreds of thousands of endpoints and applications could take years, time the IC cannot afford.

Automating Readiness with Tychon

Tychon Quantum Readiness automates cryptography discovery, inventory, and risk assessment across endpoints, networks, containers, and cloud environments. The lightweight, stateless utility deploys seamlessly through tools IC agencies already use such as BigFix, Intune, SCCM, or Ansible, with no new agents or consoles to manage.

Within hours, mission owners can see where vulnerable cryptography lives, score their risk using NIST-aligned metrics, and generate dashboards suitable for compliance reporting to OMB M-23-02 and NSM-10.

Field-proven on more than one million U.S. Government systems, Tychon demonstrates scalability that matches IC mission environments.

Risk Management, Not Reinvention

Cybersecurity has always been about risk management. Tychon brings that same maturity to quantum readiness. Helping agencies measure, analyze, mitigate, and manage cryptographic risk without disrupting existing operations or retraining staff.

Because data never leaves the customer environment and Tychon runs within existing security stacks, it aligns naturally with classified, air-gapped, and compartmented networks.

The Time to Act Is Now

Quantum readiness is no longer a research initiative. It’s a national security imperative. Agencies that begin automated cryptographic discovery today gain the time and clarity needed to meet federal timelines and stay ahead of adversaries already collecting data for future decryption. Taking action now is necessary and beneficial to agencies as it:

  • Gives leaders the facts needed to plan as early inventory provides the scope, scale, and complexity necessary to build accurate PQC budgets, staffing models, and modernization timelines.
  • Enables smart prioritization by knowing which systems use quantum-vulnerable algorithms lets agencies focus first on the highest-risk, highest-impact assets.
  • Creates leverage with vendors and integrators exposing dependencies on third-party products, giving agencies time to secure roadmaps, upgrades, and contract modifications.

 

Learn where your cryptography stands. Visit tychon.io to schedule a Quantum Readiness Assessment and receive your no-cost 90-day pilot.

About Tychon

TYCHON is a NIST NCCoE consortium collaborator and proven cybersecurity innovator delivering automated cryptography discovery and quantum-readiness solutions across U.S. Federal, DoW, and commercial enterprises. Tychon provides instant cryptographic visibility, risk assessment, and compliance reporting for the post-quantum era.

Sponsored content provided by Tychon LLC, a NIST NCCoE consortium collaborator for PQC.

About IC Insiders

IC Insiders is a special sponsored feature that provides deep-dive analysis, interviews with IC leaders, perspective from industry experts, and more. Learn how your company can become an IC Insider.

The post The Urgency of Quantum Readiness – What the Intelligence Community Needs to Know Now appeared first on Intelligence Community News.

]]>
43223
PQShield and Carahsoft partner https://intelligencecommunitynews.com/pqshield-and-carahsoft-partner/?utm_source=rss&utm_medium=rss&utm_campaign=pqshield-and-carahsoft-partner Tue, 04 Nov 2025 15:23:05 +0000 https://intelligencecommunitynews.com/?p=43098 On October 30,  PQShield, a provider of post-quantum cryptography (PQC) solutions, and Carahsoft Technology Corp. announced a new partnership. Under the...

The post PQShield and Carahsoft partner appeared first on Intelligence Community News.

]]>
On October 30,  PQShield, a provider of post-quantum cryptography (PQC) solutions, and Carahsoft Technology Corp. announced a new partnership. Under the agreement, Carahsoft will serve as PQShield’s Master Government Aggregator, making the company’s post-quantum cryptography product suite, which is compliant with new NIST PQC Standards, available to the public sector through Carahsoft’s reseller partners and NASA Solutions for Enterprise-Wide Procurement (SEWP) V, OMNIA Partners, E&I Cooperative Services Contract and The Quilt contracts.

“We are pleased to partner with Carahsoft to help government customers transition to post-quantum cryptography by 2035 to meet the deadline set by national cybersecurity agencies like the NSA and NCSC,” said Ben Packman, chief strategy officer at PQShield. “With the release of the new NIST standards, we’ve reached a critical milestone in advancing post-quantum security. Post-quantum cryptography is already making its way through the supply chain, and quantum-safe, NIST-aligned products are available today. To accelerate adoption, we not only need continued development but also greater education and clear guidance for enterprises on what these standards mean and how they affect their security responsibilities. Given that government agencies and critical national infrastructure will likely be among the first targets of quantum-enabled threats, it is essential to collaborate with partners like Carahsoft to help these institutions navigate the transition to post-quantum readiness.”

PQShield stands out for its deep expertise in NIST’s PQC standards—as co-authors of all published standards to date—and its proprietary cryptographic algorithms, patented technologies and security protocols. Its solutions are rigorously tested to meet Cloud, Edge and Government-grade requirements, aligning with certifications such as NIST, Common Criteria, SESIP and PSA.

PQShield’s products enable government departments and suppliers to reach compliance with the new PQC standards set out in regulations like the National Security Agency’s (NSA) CNSA 2.0 and NSM-10 by the 2030 timeline. They also support the transition away from vulnerable cryptographic algorithms, including the NIST-mandated phase-out of RSA by 2035.

PQShield’s varied product suite allows government department IT leaders to choose implementations of PQC that best match their priorities – something that is increasingly important for organizations that require either fast-performance, high-security or low-footprint solutions.

“The addition of PQShield’s products to Carahsoft’s solution portfolio aligns with our mission to offer the most relevant and up-to-date technology to our government customers,” said Brian O’Donnell, vice president of cybersecurity solutions at Carahsoft. “The 2035 NIST deadline means the need for compliant and secure post-quantum cryptography solutions is rapidly increasing. Carahsoft and its reseller partners are equipped and ready to meet the procurement needs of public sector organizations that still need to adopt quantum-resistant cryptographic algorithms.”

Source: Carahsoft

Time is running out — become a paid subscriber to IC News today, and lock in subscription rates at 2025 prices. You’ll get full access to breaking news from across the IC contracting space, with new articles each weekday.

The post PQShield and Carahsoft partner appeared first on Intelligence Community News.

]]>
43098
SandboxAQ launches Open Cryptography https://intelligencecommunitynews.com/sandboxaq-launches-open-cryptography/?utm_source=rss&utm_medium=rss&utm_campaign=sandboxaq-launches-open-cryptography Mon, 03 Nov 2025 14:29:04 +0000 https://intelligencecommunitynews.com/?p=43083 On October 30, SandboxAQ launched OpenCryptography.com, the first public database mapping cryptographic assets, weaknesses, and risks across the digital ecosystem. The free...

The post SandboxAQ launches Open Cryptography appeared first on Intelligence Community News.

]]>
On October 30, SandboxAQ launched OpenCryptography.com, the first public database mapping cryptographic assets, weaknesses, and risks across the digital ecosystem. The free resource translates raw cryptographic findings into clear risk signals, helping security teams identify exploitable vulnerabilities and prioritize remediation. It also gives enterprises, researchers, and policymakers unprecedented visibility into real-world cryptographic deployments across the internet, enabling them to uncover weaknesses, strengthen defenses, and modernize for the post-quantum era.

Global regulators have made it clear: organizations must act now to modernize their cryptographic foundations and reduce supply chain risk. As the Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), and National Institute of Standards and Technology (NIST) jointly stated, “It is imperative for all organizations, especially critical infrastructure, to begin preparing now for migration to post-quantum cryptography. Without open, transparent tools, enterprises remain vulnerable to attacks that exploit outdated or misconfigured encryption.”

“OpenCryptography reflects our conviction that the status quo is no longer acceptable,” said Marc Manzano, general manager of the cybersecurity group at SandboxAQ. “Cryptography needs to stop being seen as a black box or as a vendor-related problem. It is the foundational building block for digital trust. We cannot secure what we can’t see. By making this database available to everyone, we are ending cryptographic blind spots and giving the community what it needs to act now, pinpoint actual vulnerabilities faster, and accelerate post-quantum readiness.”

The initiative draws on more than a year of intensive SandboxAQ research to assemble a continuously updated inventory of cryptographic assets from widely used software and infrastructure. SandboxAQ’s database already contains almost one billion entries spanning open-source repositories, software containers, and operating system distributions. This launch will release thousands of those entries, enabling users to pinpoint weaknesses, understand how risks evolve over time, and track the adoption of next-generation cryptographic algorithms and protocols.

“The power of community has always been central to cryptography,” said Manzano. “Just as global cryptographers contributed to the U.S. National Institute of Standards and Technology (NIST) process to establish new post-quantum cryptography (PQC) standards, OpenCryptography creates a shared foundation for improving the security posture of the Internet.”

Source: SandboxAQ

Help IC News continue to bring you breaking news from across the IC and IC contracting landscape. Join our paid subscribers today.

The post SandboxAQ launches Open Cryptography appeared first on Intelligence Community News.

]]>
43083
PQCC publishes PQC Inventory Workbook https://intelligencecommunitynews.com/pqcc-publishes-pqc-inventory-workbook/?utm_source=rss&utm_medium=rss&utm_campaign=pqcc-publishes-pqc-inventory-workbook Tue, 05 Aug 2025 22:44:57 +0000 https://intelligencecommunitynews.com/?p=42363 On July 31, the Post-Quantum Cryptography Coalition (PQCC) published its Post-Quantum Cryptography (PQC) Inventory Workbook to assist organizations of all sizes in creating a centralized...

The post PQCC publishes PQC Inventory Workbook appeared first on Intelligence Community News.

]]>
On July 31, the Post-Quantum Cryptography Coalition (PQCC) published its Post-Quantum Cryptography (PQC) Inventory Workbook to assist organizations of all sizes in creating a centralized inventory to track cryptographic migration efforts.

“As highlighted within the coalition’s PQC Migration Roadmap, building an inventory is essential for effective migration planning and long-term success,” said Wen Masters, vice president of cyber technologies, MITRE. “The workbook serves as a resource to help organizations achieve their migration goals.”

The workbook provides a streamlined set of fields to assess PQC needs, plan system life cycles, and prioritize assets for migration. Organizations can use the workbook as-is or customize it to meet their specific needs, including adding fields to track additional data over time.

“The coalition continues to provide new resources to the greater cyber community to help them better manage their transition to quantum-resistant cryptographic systems,” said Matt Mickelson, lead coordinator of the PQCC and senior cyber principal for science and technology, MITRE. “This spring, the Coalition published the PQC Migration Roadmap. Now we have the inventory workbook, and we plan to publish quantum risk assessment materials later this year.”

Source: MITRE

Stay in the know with breaking news from across the IC and IC contracting landscape by becoming a paid subscriber to IC News. Your support makes our work possible.

The post PQCC publishes PQC Inventory Workbook appeared first on Intelligence Community News.

]]>
42363
Carahsoft and QuSecure partner https://intelligencecommunitynews.com/carahsoft-and-qusecure-partner/?utm_source=rss&utm_medium=rss&utm_campaign=carahsoft-and-qusecure-partner Thu, 05 Jun 2025 14:59:29 +0000 https://intelligencecommunitynews.com/?p=41885 On June 4, Carahsoft Technology Corp. and QuSecure, Inc., a leader in post-quantum cryptography (PQC), announced a partnership. Under the...

The post Carahsoft and QuSecure partner appeared first on Intelligence Community News.

]]>
On June 4, Carahsoft Technology Corp. and QuSecure, Inc., a leader in post-quantum cryptography (PQC), announced a partnership. Under the agreement, Carahsoft will serve as QuSecure’s Master Government Aggregator, making QuSecure’s products available to the public sector through Carahsoft’s reseller partners, AWS Marketplace and NASA Solutions for Enterprise-Wide Procurement (SEWP) V, Information Technology Enterprise Solutions – Software 2 (ITES-SW2), and OMNIA Partners contracts.

“With the help of Carahsoft’s world-class sales, marketing, reseller, and integrator ecosystem, we are accelerating our mission to provide the public sector with solutions that protect their most critical assets from emerging AI and quantum threats,” said Rebecca Krauthamer, co-founder and CEO at QuSecure. “QuProtect is an all-in-one network security solution designed to empower cybersecurity leaders with a flexible and resilient framework. The platform seamlessly guides organizations through every stage, from discovery to remediation, enabling effortless crypto-agility while ensuring robust protection. Administrators gain full control over cryptography algorithms, enabling them to establish a strategic cybersecurity framework tailored to the unique needs of their organization. Compliant with the National Institute of Standards and Technology (NIST) and the Quantum Computing Cyber Security Preparedness Act, QuProtect ensures alignment with industry standards while offering robust protection against evolving threats.”

With QuSecure, government agencies can ensure compliance with quantum mandates and regulatory requirements while swiftly securing critical data against AI and quantum computing threats, providing seamless protection without disrupting communications or uptime.

“As quantum computing and AI become more prevalent in today’s digital landscape, Carahsoft and our reseller partners remain dedicated to providing best-of-breed IT solutions to our public sector customers,” said Craig Abod, Carahsoft president. “We look forward to partnering with QuSecure to help the public sector address the urgent need of protecting our most sensitive data assets.”

Source: Carahsoft

Stay in the know with breaking news from across the IC and IC contracting landscape by becoming a paid subscriber to IC News. Your support makes our work possible.

The post Carahsoft and QuSecure partner appeared first on Intelligence Community News.

]]>
41885